Consider updating JQuery dependency on spring-cloud-netflix-eureka-server to 3.5.1
envgap__spring-cloud__spring-cloud-netflix-3843
01 / FAILURE SIGNATURE
As reported upstream
No identifying execution failure has been captured.
Not a benchmark task.
- In a clean container the reported failure did not reproduce, or the known fix did not make the project run.
02 / ENVIRONMENT RECIPE
- Base commit
3bd44d69ca95ef1d1ca510b5208b1108ed95b54b- Manifest
spring-cloud-netflix-eureka-server/pom.xml- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / ORIGINAL ISSUE TEXT
spring-cloud/spring-cloud-netflix #3843 · read the original issue
Hi there, we are routinely scanning our dependencies for open vulnerabilities using OWASP dependency check. On the artifact spring-cloud-netflix-eureka-server, this check reported the following vulnerabilities: CVE-2020-11022 CVE-2020-11023 I see the dependency is declared in the POM and then processed by WRO. If possible, please consider updating the JQuery dependency to 3.5.1 as per https://blog.jquery.com/2020/05/04/jquery-3-5-1-released-fixing-a-regression/ Thanks in advance. Philipp
04 / LABELS
Labels from the report text only; not yet run
No supported category has been assigned.
Label rules and the text that matched
[]